In-app reader
Relevant Products/Components:
trestle/core/commands/author/jinja.py
trestle author jinja
The -o/--output argument in trestle author jinja allows writing files outside the intended workspace.
The application does not properly validate:
../
..\
absolute paths
This allows arbitrary file write to attacker-controlled locations.
Vulnerable code:
output_file = trestle_root / r_output_file
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.